ensure wallet is saved after walletInfo is created (#3101)
What changed, and why it matters
This commit adds one line to make sure a newly created wallet is saved to disk right after its metadata record is saved. Without this save, the app might continue using or switching to a wallet whose underlying files were not yet persisted, which could lead to crashes, missing wallet data, or a user being unable to reopen the wallet later. It is a data-consistency fix rather than an obvious remote attack vector.
Treat as a reliability/data-integrity fix. Include in the next release and verify through regression tests that wallet creation, app restart, and wallet switching behave correctly. No urgent security response is indicated by the diff alone.
Security signals we found
Data persistence gap closed between walletInfo.save() and wallet activation
Potential inconsistency/corruption risk during wallet creation
No explicit security language, CVE, or attacker-controlled input in diff
Evidence from the diff
In lib/view_model/wallet_creation_vm.dart, after creating a wallet and saving credentials.walletInfo, the code now also calls await wallet.save(). The change ensures the wallet object/state is persisted before changeCurrentWallet is invoked and before the UI is told the creation succeeded. The diff alone does not show an exploit path, but it removes a window where the in-memory wallet and on-disk wallet could be inconsistent.
Changed components
lib/view_model/wallet_creation_vm.dartWallet creation flowWallet persistence layerInspect captured patch +1 / −0
diff --git a/lib/view_model/wallet_creation_vm.dart b/lib/view_model/wallet_creation_vm.dart
index 50f430ad..b2d01b39 100644
--- a/lib/view_model/wallet_creation_vm.dart
+++ b/lib/view_model/wallet_creation_vm.dart
@@ -131,6 +131,7 @@ abstract class WalletCreationVMBase with Store {
credentials.walletInfo!.hashedWalletIdentifier = createHashedWalletIdentifier(wallet);
credentials.walletInfo!.address = wallet.walletAddresses.address;
await credentials.walletInfo!.save();
+ await wallet.save();
await _appStore.changeCurrentWallet(wallet);
_appStore.authenticationStore.allowedCreate();
state = ExecutedSuccessfullyState();
Why this scored 24/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.